Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

101–110 of 201 posts

Re: A billion medical images are exposed online

#101
post #70

Earlier quoted context omitted.

I'm a student doctor with a CS undergrad. I'm constantly gobsmacked by how horrible the computer systems doctors are forced to use are. They're pretty much abusive to use. The hours and hours of physician time that are thrown away into mindless box-ticking, copy-pasting, button-pushing, and general head-banging is astounding. If doctors are resistant to new IT hurdles it is, at least in part, because they're already…

Yep. Never blame users for raging at the system until you understand the system as well as they do. Techies have it easy: they only have one job and that’s all they ever do. It looks very different from the other side. (Protip: The key to delivering successful software is not to learn programming, it is to learn your users.) (Oh, and good luck with your medical studies; world needs good Renaissance [Wo]Men now more t…

> (Oh, and good luck with your medical studies; world needs good Renaissance [Wo]Men now more than ever.)

Why now more than ever?

Re: A billion medical images are exposed online

#102

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

"An attacker then used those credentials to breach the network and siphoned several hundred thousand dollars from the financial system (wiring money to himself)."

You're telling me the CEO was unfazed when they learned this was the reason you were locking down the system due to the doctor's own ineptitude and breaking company policy looking at porn and exposing them to direct financial loss and liability (lawsuits from PII data being breached and exfiltrated, etc)?

The doctor put the whole hospital at risk and could have cost them millions and got that cryptolocker attack holding their data hostage indefinitely.

The CEO should be thanking you guys for catching these huge security ($$$) breaches.

Re: A billion medical images are exposed online

#103

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

That exact attitude the doctors have is so common in other occupations, I’ve experienced it with lawyers.

Re: A billion medical images are exposed online

#105

Earlier quoted context omitted.

People are constantly targeting every aspect of the physician workflow, from CMS and private payors constantly changing their documentation requirements (which differ between payors and CMS, and results in hospitals trying to teach their docs to document everything to meet everyone's requirements - which are made intentionally lengthy and obtuse so as to justify denials of payment), quality improvement people and ven…

I'm sympathetic to this, and in other threads I would usually be the first person coming to the defense of doctors and harping on how complex and terrible EMR and other medical software is. But that's not what I'm talking about. I'm not talking about complex software. I'm not talking about instances where doctors are asked to learn an entirely new records management or scheduling system. I'm not talking about the typ…

> Except in one instance we had delays rolling out SSO not because the system was complicated to use, but because doctors complained that they didn't like the color of the SSO UI. They insisted it be blue rather than yellow and wanted to scrap the entire project because of it. That's the type of resistance I'm talking about.

Is it really the hill you want to die on?

Just change the damn widget color if it is so important to them! Client is king!!

Re: A billion medical images are exposed online

#106
post #102

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

"An attacker then used those credentials to breach the network and siphoned several hundred thousand dollars from the financial system (wiring money to himself)." You're telling me the CEO was unfazed when they learned this was the reason you were locking down the system due to the doctor's own ineptitude and breaking company policy looking at porn and exposing them to direct financial loss and liability (lawsuits fr…

I wouldn't say unfazed, but as I recall the reaction was more that the doctor wasn't to be blamed and that it was security's fault for not only "allowing" the breach to happen, but also for inconveniencing the doctor.

At the organizations I worked with, doctors really have carte blanche privilege to get away with anything as long as they claim "it's for a patient". Even the C-suite will bend over backwards for MDs.

Re: A billion medical images are exposed online

#107
post #25

Earlier quoted context omitted.

> One of them spends almost as much time on data entry as he does with patients ...then he’s one of the lucky ones! One study found that for every hour a physician spends with a patient, she spends two on processing health records. https://www.jwatch.org/fw111995/2016/09/06/half-physician-ti...

I mean, for every hour I spend writing production code - I spend an hour in agile meetings, and 2 hours chasing down obscure bugs in javascript libraries. Not that many professions are "do visible part of work 100%". Heck, I hear bricklayers need to spend some time mixing cement and getting bricks off the truck, not just scooping mud and sticking bricks. Health records ARE a big part of the product of a doctor. Keepi…

> Health records ARE a big part of the product of a doctor

I long for practices that would keep no record of my issues, except what I volunteer to them at the beginning of the consult. Many countries do that just fine, but for some reason in the US I am asked to fill pages on insignificant trivia to cover their ass or follow some weird law or tradition maybe?

I don't want perfect healthcare. Good enough is fine!

So now I just see doctors when traveling. Simpler, faster, and cheaper too.

Re: A billion medical images are exposed online

#108
post #47

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…

>Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues.

That statement applies to about 95% of the many issues we face these days. Blaming is apparently easier than solving.

Re: A billion medical images are exposed online

#109

Earlier quoted context omitted.

In contrast to your experience, all VA physicians are obligated to use an ID card with a chip in order to login.

Indeed, other hospital chains do as well, which is why we viewed it as a good option and went down that path to begin with. In the case I'm referring to, everyone at the hospital already had badges and the thought was that removing password requirements and using the badges that everyone already had as a login would work well. It didn't work, not because of technical issues, but because we didn't anticipate the high…

Physicians sporadically not having badges sounds like an accreditation-threatening problem, for what it’s worth. (It depends on the institution’s self-stated standards, however.)

Re: A billion medical images are exposed online

#110

On the user side, we have to jump through hoops and sign so many onerous paper HIPAA compliance forms at dr’s offices, to just get doctors to share records about us. On the backend it’s free for anyone to access. It’s all backwards!

The signature demands that really annoy me are the ones in which I must acknowledge that the provider has informed me of their HIPAA policies, which demands are seldom accompanied by actual information about HIPAA policies, which I probably wouldn't read anyway even if they were included.

Then refuse to sign: you can't be denied care for refusing communication of your records to 3rd parties. It's certainly better for your privacy too.
Post reply on HN